Wednesday , September 16 2026

Pillar 4: Total 131 Indicators Set
How Bangladeshi’s Ogrs Be Evaluated By Newly Launched NRS & CIRS

Bangladesh’s National Cyber Security Agency (NCSA) has launched two cybersecurity initiatives: the Cyber Incident Reporting System (CIRS) and the National Rating System (NRS). These aim to help manage cyber incidents better and improve the cybersecurity skills of organizations in the country.

These initiatives aim to build a system for reporting cyber incidents, central monitoring, and uniform cybersecurity checks for government and private organizations.

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Palo Alto Networks has revealed a serious flaw in PAN-OS. It may let a remote attacker without a password run...
Read More
Palo Alto PAN-OS Flaw Enables Root Arbitrary Code Execution

Critical Check Point VPN flaws allow remote code execution attacks

Check Point Software has revealed and fixed two major VPN flaws, CVE-2026-85102 and CVE-2026-85103. Both have a top CVSS score...
Read More
Critical Check Point VPN flaws allow remote code execution attacks

Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Cisco has said that a serious security flaw CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being used...
Read More
Cisco confirms CVE-2026-20079 flaw in Secure FMC is exploited in attacks

Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

A Russian-speaking hacker has used artificial intelligence like never before. They sent out hundreds of AI agents to find and...
Read More
Hackers exploit PaperCut flaws using hundreds of AI agents, compromising 440 servers globally

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according to U.S. cybersecurity and intelligence...
Read More
CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Cyber Incident Reporting System (CIRS)

Cyber Incident Reporting System (CIRS) is a simple online platform for citizens, organizations, and approved users to report cyber events easily to (report.ncsa.gov.bd).

Users can send reports about cyber fraud, online harassment, unauthorized access, data breaches, harmful content, and other cyber issues according to the NCSA document. The platform lets users upload proof, add website or social media links, get a Complaint ID automatically, and check the status of their reports during the investigation.

Each submitted report follows a defined workflow that includes:

Complaint submission
Verification
Analysis
Escalation
Response
Monitoring
Resolution

Source: NCSA

Reports can start at the Upazila level. If needed, they can go up to the District level. For complicated or important cases, they are sent to the National Cyber Security Agency (NCSA).

Source: NCSA

Dashboard and Inter-Agency Coordination

The CIRS platform includes role-based dashboards for monitoring:

Total reported incidents
New reports
Reports under verification
Resolved cases
Escalated incidents
Category-based statistics
District and Upazila trends
High-priority cyber incidents
Time-based performance indicators

The framework also suggests sharing information among agencies like NSI, BTRC, and law enforcement to help with better decision-making and to understand the national cyber situation.

Source: NCSA

Future Roadmap for CIRS

The NCSA document outlines several future enhancements planned for the platform, including:

AI-based trend analysis
Risk scoring
Early warning capabilities
Intelligence-sharing modules
Fact-checking functionality to verify viral information and misinformation
Secure sharing of phishing indicators, malicious domains, and other threat intelligence

National Rating System (NRS)

NCSA has also unveiled the National Rating System (NRS) based on a framework that rates the maturity of ICT and cyber security.

The framework aims to create a standard way to assess ICT, information security, and cybersecurity skills in both public and private organizations in Bangladesh. It seeks to find strengths, weaknesses, and spots that need better cybersecurity.

Four Assessment Pillars:

Organizations will be evaluated across four weighted categories:

IT & Information Security Governance:             20%
Infrastructure & Operations:                             30%
Cyber Security & Data Protection:                    30%
Digital Service & User Maturity:                        20%

The framework uses a scale from 0 to 4 to check how well organizations are doing, from not started to fully developed and optimized.

131 Assessment Indicators

Organizations will be judged based on 131 assessment indicators. These indicators were created to match global standards, frameworks, and best practices in cybersecurity.

Overall scores will determine institutional grades, ranging from:

A – Excellent
B – Very Good
C – Good
D – Fair
E – Poor

Expected Benefits

The framework identifies several expected outcomes, including:

Establishing a national cybersecurity maturity baseline.
Identifying institutional risks and capability gaps.
Supporting IT audits and Vulnerability Assessment and Penetration Testing (VAPT) prioritization.
Assisting organizations with cybersecurity planning, budgeting, and workforce development.
Strengthening national cyber resilience and evidence-based policymaking.

Future plans involve using AI for automatic assessments, checking evidence automatically, dashboards for comparing different sectors, and advice based on risks for organizations.

Why It Matters

The Cyber Incident Reporting System (CIRS) and the National Rating System (NRS) are two key parts of Bangladesh’s growing cybersecurity setup. CIRS aims to make reporting incidents, working together, and responding better. NRS provides a standard way to measure and improve cybersecurity levels in organizations. If these plans are followed as described in the NCSA documents, they should help see cyber threats better, boost readiness, and help Bangladesh become more resilient digitally.

Bangladesh Launches (CIRS) and National ICT & Cyber Security Rating System (NRS)

Check Also

AIDCQ

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades …